SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
A high-severity remote code execution (RCE) vulnerability in Microsoft SharePoint Server (CVE-2026-45659) has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog due to active exploitation, despite Microsoft's earlier "Exploitation Less Likely" assessment.
Intelligence analysis by Gemini 2.5 Flash

CISA has flagged a critical SharePoint RCE flaw, CVE-2026-45659, for active exploitation, urging federal agencies to patch immediately. This comes after Microsoft recently uncovered two distinct threat actors, including Storm-2603, simultaneously exploiting vulnerabilities in SharePoint environments, highlighting the complex and persistent nature of modern cyberattacks.
Imagine a secret door in a big office building (SharePoint) that bad guys found a way to open, even though the building managers (Microsoft) thought it was pretty secure. Now, a special security team (CISA) is telling everyone to quickly fix that door because bad guys are already using it to sneak in and cause trouble. It's like a game of hide-and-seek where the bad guys are very tricky.
Analysis
The Actively Exploited SharePoint Flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently added a high-severity vulnerability, CVE-2026-45659, affecting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog. This flaw, with a CVSS score of 8.8, is categorized as a remote code execution (RCE) vulnerability, specifically arising from the deserialization of untrusted data. Microsoft had previously issued a patch for this issue in May 2026, covering SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
Notably, Microsoft's initial assessment had tagged this flaw with an "Exploitation Less Likely" rating. However, CISA's decision to include it in the KEV catalog directly contradicts this, citing clear evidence of active exploitation in the wild. The vulnerability can be triggered by any authenticated attacker with a minimum of Site Member permissions, meaning it does not require administrative or elevated privileges, making it a significant threat vector for organizations utilizing SharePoint.
CISA's Urgent Directive and Unknowns
CISA's inclusion of CVE-2026-45659 in its KEV catalog serves as a critical alert, particularly for Federal Civilian Executive Branch (FCEB) agencies. These agencies are now mandated to apply the necessary fixes by July 4, 2026, emphasizing the immediate and severe risk posed by the vulnerability. This directive underscores the urgency for all organizations, not just federal entities, to prioritize patching their SharePoint environments.
Despite the confirmation of active exploitation, the article notes that specific details regarding how the vulnerability is being exploited, the identities of the threat actors involved, and their ultimate objectives remain largely unknown. This lack of detailed intelligence can complicate defensive efforts, as security teams must act swiftly based on the confirmed threat without full insight into the attack methodologies.
Broader Threat Landscape: Parallel Attacks
The context of this SharePoint RCE vulnerability is further complicated by Microsoft's recent revelation of parallel threat activity. Late last month, during a routine ransomware investigation, Microsoft uncovered two unrelated threat actors operating simultaneously within the same network. These actors employed deliberate techniques to establish persistent access and complicate incident response efforts, highlighting a sophisticated and multi-layered approach to cyberattacks.
One of these attack clusters has been attributed to Storm-2603, a known threat actor notorious for deploying Warlock ransomware, often by exploiting known vulnerabilities in on-premises SharePoint servers since mid-2025. While the initial access in this specific parallel incident was likely through a different flaw (CVE-2025-11371 impacting Gladinet Triofox), Storm-2603's historical focus on SharePoint underscores the platform's attractiveness to attackers. The group utilized tools like Velociraptor, established multiple remote access channels via Cloudflare tunneling, Zoho Assist, and SSH, and escalated privileges by creating new administrator accounts, even tampering with endpoint security protections. The co-existence of a second, unrelated threat actor using DLL side-loading and custom backdoors further illustrates the complexity, making attribution and comprehensive remediation exceptionally challenging for affected organizations.
Key points
- CVE-2026-45659, a high-severity RCE flaw in Microsoft SharePoint Server, has been added to CISA's KEV catalog.
- The vulnerability, stemming from deserialization of untrusted data, allows authenticated attackers with Site Member permissions to execute code remotely.
- Microsoft had previously assessed the flaw as "Exploitation Less Likely" but patched it in May 2026.
- CISA mandates Federal Civilian Executive Branch agencies to apply fixes by July 4, 2026, due to active exploitation.
- Microsoft recently uncovered two distinct threat actors, including Storm-2603, simultaneously exploiting vulnerabilities in SharePoint environments, using advanced techniques to maintain persistence.
The rapid addition of CVE-2026-45659 to CISA's KEV catalog ensures that federal agencies are immediately alerted and mandated to apply patches, potentially limiting the scope and impact of ongoing exploitation. Microsoft's detailed reporting on parallel threat activity also provides valuable intelligence for organizations to enhance their defensive strategies against sophisticated, multi-pronged attacks.
Despite Microsoft's patch availability since May 2026, the active exploitation of CVE-2026-45659 indicates that many organizations may still be vulnerable, leaving them exposed to remote code execution. The discovery of multiple, unrelated threat actors operating simultaneously within compromised networks suggests a highly complex and persistent threat landscape, making detection and complete remediation exceptionally challenging for security teams.



